That's not conceptually much different from port scanning then. And that's against the law around here. Just kidding. But unless they're going to push some Flash on the site I really don't see what business they have trying to detect if I have Flash anyway. "Passive detection" might be passable but such "active detection" by brute forcing is questionable.
Also whether or not I have Flash installed is a very personal matter, I didn't sign up to give that information to 3rd parties. There's nothing about such in the Privacy/Terms of use that I could see. 
This inspired me to look into the InPrivate filtering feature in IE8 but seems that it's not built to block this kind of privacy invasion.